nerdexam
EC-Council

312-39 · Question #34

You are a Level 1 SOC analyst at a critical infrastructure provider. Threat actors infiltrated the network and exfiltrated sensitive system blueprints. Before detection, they executed commands that…

The correct answer is C. Cleanup. Cleanup is the phase where adversaries attempt to cover their tracks and reduce the chance of detection or attribution. The described behaviors-altering logs, wiping forensic artifacts, modifying timestamps, and tampering with monitoring tools-are classic defense evasion and…

Threat Intelligence

Question

You are a Level 1 SOC analyst at a critical infrastructure provider. Threat actors infiltrated the network and exfiltrated sensitive system blueprints. Before detection, they executed commands that altered system logs, wiped forensic artifacts, and modified timestamps to mimic normal activity. They also manipulated security monitoring tools to prevent unusual login events from being recorded. Which APT lifecycle phase does this represent?

Options

  • ASearch and Exfiltration
  • BInitial Intrusion
  • CCleanup
  • DExpansion

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    5% (2)
  • C
    71% (27)
  • D
    8% (3)

Explanation

Cleanup is the phase where adversaries attempt to cover their tracks and reduce the chance of detection or attribution. The described behaviors-altering logs, wiping forensic artifacts, modifying timestamps, and tampering with monitoring tools-are classic defense evasion and anti-forensic actions. In SOC investigations, these actions indicate the attacker is prioritizing stealth and persistence after completing objectives, making reconstruction more difficult. Search and exfiltration focuses on locating valuable data and transferring it out; while that happened earlier, the key activities described are about removing evidence and obscuring the timeline. Initial intrusion refers to the first entry (phishing, exploit, stolen credentials). Expansion refers to broadening access (lateral movement, privilege escalation) across the environment. The scenario explicitly emphasizes manipulating logs and monitoring to hide activity and prevent alerts, which aligns most closely with cleanup. For defenders, this phase drives urgency: isolate affected systems, preserve volatile data quickly, validate logging pipelines, and use independent telemetry sources (network flows, cloud control-plane logs, immutable logging) to rebuild the attack chain despite tampering.

Topics

#APT lifecycle#anti-forensics#log tampering#cleanup phase

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice